Skip to content

Harden REST API authentication, thread safety and lifecycle - #3

Merged
SrBedrock merged 7 commits into
masterfrom
fix/issue-1-rest-hardening
Sep 28, 2026
Merged

SrBedrock merged 7 commits into
masterfrom
fix/issue-1-rest-hardening

Conversation

@SrBedrock

@SrBedrock SrBedrock commented Sep 28, 2026 •

Copy link
Copy Markdown
Member

Closes #1

  • Require exact tokens on both player and server endpoints; reject invalid token configurations and remove secret logging.
  • Serialize responses with Gson while retaining the existing string status and message fields.
  • Run Bukkit and PlaceholderAPI lookups on the main thread with a timeout, per-peer rate limit, and concurrency cap.
  • Distinguish unknown placeholders from valid empty results.
  • Stop the HTTP listener on disable; reload and validate configuration, switch listener, and roll back after bind failures.
  • Configure bind and peer IP allowlist, document Docker/Pterodactyl plus HTTPS proxy setup, and add regression tests and a CI workflow.
  • Remove a machine-specific Windows org.gradle.java.home setting so builds use the selected JDK.

Build update: Java 25 toolchain and CI, Paper API 1.21.11, Gradle wrapper 9.8.0, Shadow 9.6.1 and PlaceholderAPI 2.12.3. Updated JUnit launcher and Mockito for Java 25.

Validation: GitHub Actions Build run Fredthedoggy#6 passed bash gradlew test shadowJar --no-daemon on JDK 25.

@SrBedrock

Copy link
Copy Markdown
Member Author

@codex review

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: 22ae2c24b2

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/main/java/me/fredthedoggy/restpapi/RestPapiLoader.java Outdated
Comment thread .github/workflows/build.yml Outdated
Comment thread build.gradle
@SrBedrock
SrBedrock merged commit 8d13195 into master Sep 28, 2026
1 check passed
@SrBedrock
SrBedrock deleted the fix/issue-1-rest-hardening branch September 28, 2026 12:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Security/Refactor] Harden REST authentication, response handling, thread safety and server lifecycle

1 participant